CVE-2011-2592
high · 9.3Heap-based buffer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to execute arbitrary code via a long CSEC HTTP response header.
9.3
CVSS
14.9%
EPSS (exploit prob.)
97th
EPSS percentile
2014-06-18
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| citrix | access_gateway_plug-in | 9.0 |
| citrix | access_gateway_plug-in | 9.1 |
| citrix | access_gateway_plug-in | 9.2 |
| citrix | access_gateway_plug-in | 9.3 |
| citrix | access_gateway_plug-in | 10.0 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/bugtraq/2012-08/0009.html
- http://osvdb.org/show/osvdb/84433
- http://secunia.com/secunia_research/2012-27
- http://support.citrix.com/article/CTX134303
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77316
- http://archives.neohapsis.com/archives/bugtraq/2012-08/0009.html
- http://osvdb.org/show/osvdb/84433
- http://secunia.com/secunia_research/2012-27
- http://support.citrix.com/article/CTX134303
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77316
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-2592